# A new breed of RAT. Page: https://stenobird.com/podcast/research-saturday-1377435/a-new-breed-of-rat Text version: https://stenobird.com/podcast/research-saturday-1377435/a-new-breed-of-rat.md Podcast: [Research Saturday](https://stenobird.com/podcast/research-saturday-1377435) Published: 2026-04-18T05:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/421/notes Audio file: https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW8137946432.mp3?updated=1776448577 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/a-new-breed-of-rat Duration seconds: 1312 ## Resource Today we are joined by Dr. Darren Williams, Founder and CEO of BlackFog, to discuss his team's work on "Steaelite RAT Enables Double Extortion Attacks from a Single Panel." A new remote access trojan, Steaelite, is being marketed on underground forums as an all-in-one platform that combines remote access, credential theft, surveillance, and ransomware deployment through a single browser-based dashboard. Unlike traditional cybercrime toolchains, it merges data exfiltration and ransomware capabilities into one interface, with automated credential harvesting beginning as soon as a victim is infected. The tool signals a growing shift toward streamlined “double extortion” attacks, where data theft and encryption happen within the same system—raising the stakes for defenders to stop threats before data is exfiltrated. The research and executive brief can be found here: Steaelite RAT Enables Double Extortion Attacks from a Single Panel ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/a-new-breed-of-rat/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/research-saturday-1377435/a-new-breed-of-rat.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.